Be wary of disguised Microsoft OneNote Audio phishing emails
Online scammers are trying to create more sophisticated and unpredictable methods to convince victims to provide them with login information and other valuable personal data. The case below is a typical example.
This new phishing campaign involves OneNote Audio Note, which has just been deployed worldwide and has begun to "welcome" the first victims. Specifically, this phishing campaign appears as an email to the target with the subject "New Audio Note Received" (roughly translated: You have received a new audio note), with the content announcing that you received a new audio message, sent from a contact in the address book. However, to listen to the message content, you will have to click on the link that is available below - that's the malicious link.
- Facebook's Libra electronic currency has not yet set a launch date but scam tricks are ready
Phishing email content
There is a noticeable feature: fraudulent scammers now often add footer notes that indicate this email is absolutely safe because it has been scanned by security software. For example, in this case, the hacker said that the email was "Scanned by McAfee Ultimate 2019 exclusive antivirus service for Microsoft" (Scanned by McAfee Ultimate 2019 Antivirus Scanning Service for Microsoft).
Also, this note will make the email more 'professional', easily fooling inexperienced people.
When you click on the "Listen to full message here" link (in case the device is connected to the internet), you will immediately be directed to the fake OneNote Online page, hosted on Sharepoint.com server. This page again reports that you have a new audio message (You have a new audio message), and then prompts you to click on another link to hear the message.
- The winning scam from Google: 'The cat game' for the vigilant, 'tragic' for those who are light-hearted
OneNote fake online page
When clicking on the link to listen to Audio Note, you will continue to be taken to another Sharepoint.com hosting site (currently disabled). Now is the time when this phishing trick is actually 'visible', you will be prompted to sign in with your Microsoft account to listen to the message. And of course if you follow, all your Microsoft account login information will fall into the hands of hackers.
This fake page may look similar to the image below, often used by various phishing scams, accurately simulating the interface of Microsoft services login pages like OneNote, Office 365 and Outlook. If you don't pay close attention, you'll be fooled and assume that this is Microsoft's "genuine" login page.
- New Android Trojans lead users to phishing websites by notification on the application
The fake Microsoft account login page
The phishing pages mentioned above are stored on Sharepoint.com server, so they will also come with a legitimate certificate from Microsoft. This detail helps them become more reliable in the victim's eyes.
Microsoft fake certificate
In general, this form of fraud has been more sophisticated, but is not new in nature. Even so, it will still be dangerous for ordinary users who don't have much knowledge about security.
- Warning: Accessing the personal page of a comment about a scam can be robbed of a Facebook nick
For Microsoft accounts and Outlook.com login information, there is an important thing to remember: Microsoft login forms will only be available on legitimate domains like microsoft.com, live.com. , microsoftonline.com and outlook.com. If you are provided with a Microsoft login form but originating from any other URL, it is best to avoid it because it is more likely to be a phishing site, designed to collect victim login information. multiply.
You should read it
- 7 forms of fraud, popular online fraud
- How to identify phishing emails
- 25% of 'over-the-counter' phishing emails are the default security of Office 365
- Apple shows users how to distinguish phishing emails from the App Store
- [Infographic] How to recognize and prevent Phishing attacks
- Google wants to test user knowledge about phishing emails
- How to report phishing emails in Outlook.com
- Microsoft shows how to avoid trapping phishing
May be interested
- How to use OneNote templateonenote 2016 has a lot of page templates. they provide you with built-in layouts with a variety of formatting options, helping you create clear and structured notes accordingly.
- Microsoft has just freeed all features on OneNotemost vietnamese and especially office workers should be familiar with software from microsoft such as word, excel, powerpoint and outlook when they provide full features to support the daily work. however, in the office installation package, there is still one more software that many people have not noticed until now, that is onenote.
- If you see this email in your inbox, delete it immediately!inboxes are flooded with fake messages, but they go undetected by spam filters - anyone can receive them.
- Apple shows users how to distinguish phishing emails from the App Storeapple has just published a guide on how to distinguish fraudulent emails.
- Top 5 Sites to Download Free OneNote Templateswhether you need a comprehensive project management template, a visually appealing meeting agenda, or a beautifully designed collection of recipes, there's a template to suit your needs.
- How to crop pictures in OneNote app?to crop pictures in microsoft onenote web, you first need to sign in to the onenote website from any browser. on the notebook screen, select the note document ...
- Why should I switch from OneNote 2016 to OneNote for Windows 10?onenote is great for tracking and organizing all information and is available on all devices. microsoft currently offers two versions of onenote: onenote for windows 10 and onenote 2016
- New phishing attacks appear to use Google Translate as a disguiserecently, a phishing campaign to steal google accounts and facebook login information has been discovered using google translate (google translate) as a disguised location on mobile browsers.
- Steps to use feeds in OneNotethe feed in onenote will combine notes from different applications, including samsung notes onenote and sticky notes when we are signed in with the same microsoft account.
- Microsoft urgently warns about a phishing campaign that uses malicious Excel macros to hack PCssecurity team with microsoft's security intelligence has issued an urgent warning about a massive fraud campaign.